☁️ SOC 2 Trust Services Criteria Assessment ✧ クラウドセキュリティ監査 ☁️
☁️
🌤️
☁️
✧ Cloud Security Assessment ✧

SOC 2ソックツー Compliance Checker

トラストサービス基準 コンプライアンスチェッカー ♪

🔐 Security
⏰ Availability
⚙️ Processing
🤫 Confidentiality
👤 Privacy

Assess your SOC 2 readiness with our kawaii Trust Services Criteria checker! ✧ Evaluate all 5 criteria to prepare for your Type I or Type II audit. がんばって!

SOC 2 Cloud Guardian
Let's check your
cloud security! ✧
クラウドを守ろう!

✧ SOC 2 Assessment ✧

トラストサービス基準チェック開始!

☁️ About SOC 2

SOC 2 (Service Organization Control 2) is an AICPA framework evaluating how service organizations manage customer data based on five Trust Services Criteria. It's essential for SaaS, cloud providers, and any organization handling customer data.

📋 Type I

Design of controls at a point in time

📊 Type II

Design + effectiveness over 6-12 months

0 of 25 questions answered ✧ 0/25 回答済み
🔐

Security (Required)

セキュリティ • Protection against unauthorized access

CC Series • Common Criteria
1

Do you have documented security policies reviewed at least annually?

少なくとも年次でレビューされる文書化されたセキュリティポリシーがありますか?
2

Is there a formal risk assessment process conducted at least annually?

少なくとも年次で実施される正式なリスク評価プロセスがありますか?
3

Do you have logical access controls with role-based permissions?

ロールベースの権限を持つ論理的アクセス制御がありますか?
4

Is multi-factor authentication (MFA) required for system access?

システムアクセスに多要素認証(MFA)は必須ですか?
5

Do you perform background checks on employees before granting access?

アクセス権付与前に従業員のバックグラウンドチェックを実施していますか?
6

Is there a documented incident response plan that's tested regularly?

定期的にテストされる文書化されたインシデント対応計画がありますか?
7

Are vulnerability scans and penetration tests conducted at least annually?

脆弱性スキャンとペネトレーションテストは少なくとも年次で実施していますか?

Availability

可用性 • System availability for operation and use

A Series • Availability Criteria
8

Do you have documented SLAs with uptime commitments?

稼働時間のコミットメントを含む文書化されたSLAがありますか?
9

Is there a disaster recovery plan with defined RTOs and RPOs?

RTOとRPOが定義された災害復旧計画がありますか?
10

Do you have redundancy and failover mechanisms for critical systems?

重要システムに冗長性とフェイルオーバー機構がありますか?
11

Is system capacity monitored with alerts for threshold breaches?

システム容量は閾値超過時のアラート付きで監視されていますか?
⚙️

Processing Integrity

処理の完全性 • Complete, accurate, timely, authorized processing

PI Series • Processing Criteria
12

Are data input validation controls implemented to ensure accuracy?

正確性を確保するためのデータ入力検証コントロールが実装されていますか?
13

Is there error handling and correction procedures documented?

エラー処理と修正手順は文書化されていますか?
14

Are processing outputs reviewed for completeness and accuracy?

処理出力の完全性と正確性がレビューされていますか?
🤫

Confidentiality

機密性 • Protection of confidential information

C Series • Confidentiality Criteria
15

Is confidential information identified and classified?

機密情報は識別・分類されていますか?
16

Is confidential data encrypted at rest and in transit?

機密データは保存時と転送時に暗号化されていますか?
17

Are there procedures for secure disposal of confidential information?

機密情報の安全な廃棄手順がありますか?
18

Do NDAs/confidentiality agreements cover employees and third parties?

NDA/機密保持契約は従業員と第三者を対象としていますか?
👤

Privacy

プライバシー • Collection, use, retention, disclosure of personal information

P Series • Privacy Criteria
19

Do you have a published privacy notice explaining data practices?

データ取扱いを説明する公開されたプライバシー通知がありますか?
20

Do you obtain consent before collecting personal information?

個人情報収集前に同意を取得していますか?
21

Can data subjects access, correct, and delete their personal data?

データ主体は自分の個人データにアクセス、修正、削除できますか?
22

Is personal data only used for disclosed purposes?

個人データは開示された目的のみに使用されていますか?
📋

Common Controls

共通コントロール • Organizational governance and operations

CC1-CC9 • Control Environment
23

Is there a formal change management process for system changes?

システム変更に対する正式な変更管理プロセスがありますか?
24

Do you assess and monitor third-party/vendor risks?

第三者/ベンダーリスクを評価・監視していますか?
25

Do all employees receive security awareness training at least annually?

全従業員が少なくとも年次でセキュリティ意識向上トレーニングを受けていますか?
0%
SOC 2 Readiness Score
Calculating...

✨ Recommendations ✧ 推奨事項 ✨

Need SOC 2 Compliance Help? ☁️✧

Our team helps SaaS companies and service providers achieve SOC 2 Type I and Type II certification. From readiness assessment to audit support, we guide you through the entire process!

💌 Get Free Consultation ✧ 無料相談
Copied! コピーしました!

Understanding SOC 2 Compliance

What is SOC 2?

SOC 2 (Service Organization Control 2) is an auditing framework developed by the AICPA that evaluates how organizations manage customer data. It's based on five Trust Services Criteria: Security (required), Availability, Processing Integrity, Confidentiality, and Privacy.

SOC 2 Type I vs Type II

The 5 Trust Services Criteria

  1. Security (CC Series): Required for all SOC 2 reports - protection against unauthorized access
  2. Availability (A Series): System availability per agreed SLAs
  3. Processing Integrity (PI Series): Complete, accurate, timely, authorized processing
  4. Confidentiality (C Series): Protection of confidential information
  5. Privacy (P Series): Personal information handling aligned with privacy notice

Who Needs SOC 2?

SOC 2 is essential for SaaS companies, cloud service providers, data centers, MSPs, and any organization handling customer data. Enterprise customers increasingly require SOC 2 Type II reports from vendors.

✧ Frequently Asked Questions ✧

What is SOC 2?
SOC 2 is an AICPA auditing framework that evaluates how service organizations manage customer data based on five Trust Services Criteria. It's the standard for demonstrating security controls to enterprise customers.
What's the difference between Type I and Type II?
Type I evaluates control design at a point in time. Type II evaluates both design AND operating effectiveness over 6-12 months. Type II is more rigorous and preferred by enterprise customers.
How long does SOC 2 take?
Type I: 2-4 months readiness + audit. Type II: 6-12 month observation period + 1-2 months audit. Total: 3-6 months for Type I, 9-18 months for Type II from scratch.
How much does SOC 2 cost?
Typical costs: Readiness assessment ($10K-$30K), Type I audit ($20K-$60K), Type II audit ($30K-$100K+), plus compliance tools. Smaller companies may spend $50K-$100K total for initial certification.
🔮

Free Security Scan for Your Website

Our Mewtwo Security Scanner checks your site for HTTPS, SSL certificates, security headers, and vulnerabilities—instantly and free.

✓ HTTPS Check ✓ SSL Analysis ✓ Security Headers ✓ Instant Results
Scan Now Free